Privacy Notice
Westfield Medical Centre is committed to protecting your personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Data Controller
Westfield Medical Centre, 47 Westfield Road, Kingsfield, Bristol BS7 9HT
Data Protection Officer: Mrs Sarah Mitchell (s.mitchell@westfield-mc.nhs.uk)
What data we collect
- Name, address, date of birth, NHS number
- Medical history, diagnoses, test results
- Prescription records
- Correspondence with other healthcare providers
- Contact details and next of kin
Legal basis
We process your data under Article 6(1)(e) of UK GDPR (public task) and Article 9(2)(h) (health purposes). We also comply with the common law duty of confidentiality and the Caldicott Principles.
Data sharing
We share data with NHS organisations directly involved in your care, including hospitals, community services, and pharmacies via the NHS Spine. We participate in NHS data sharing programmes including the Summary Care Record.
Your rights
You have the right to access your records (Subject Access Request), correct inaccurate data, restrict processing, and object to data sharing. Contact the Data Protection Officer to exercise these rights.
ICO
If you are not satisfied with how we handle your data, you can complain to the Information Commissioner's Office: ico.org.uk | 0303 123 1113